Westminster Ingleside King Farm Presbyterian Retirement Communities
Disclosed Jan 19, 20188 years ago5,228 affectedConfirmed
An unauthorized user accessed the covered entity’s (CE) information technology (IT) network and infected it with malware. The breach involved the protected health information (PHI) of 5,228 individuals and included names, addresses, dates of birth, social security numbers, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and provided free credit monitoring. Following the breach, the CE implemented dual-factor authentication for access to its IT network and a monitoring system to detect unauthorized access. During the investigation, OCR reviewed the CE’s HIPAA policies and risk analysis for HIPAA compliance.
What is known
| People affected | 5,228 (as reported to HHS) |
|---|---|
| Disclosed | Jan 19, 2018 |
| Happened | Nov 21, 2017 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Health, Financial, Addresses |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: Westminster Ingleside King Farm Presbyterian Retirement Communitiesmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Westminster Ingleside King Farm Presbyterian Retirement Communities (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | Jan 19, 2018 | 12 |
| HHS archivetotal | Jan 19, 2018 | 5,228 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn","health","financial","addresses","names"] to ["names","ssn","health","financial","addresses"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 5228 · backfill source
- 2026-09-25 · summary: empty to An unauthorized user accessed the covered entity’s (CE) information technology (IT) network and infected it with malware. The breach involved the protected health information (PHI) of 5,228 individuals and included names, addresses, dates o · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.
Everything about Westminster Ingleside King Farm Presbyterian Retirement Communities